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We propose a multiparty quantum cryptographic protocol. Unitary operators applied 

0^ ' by Bob and Charlie, on their respective qubits of a tripartite entangled state encodes a 

O 

. classical symbol that can be decoded at Alice's end with the help of a decoding matrix. 

CN ■ 

Eve's presence can be detected by the disturbance of the decoding matrix. Our protocol 
O ' is secure against interccpt-rcsend attacks. Furthermore, it is efficient and deterministic in 



the sense that two classical bits can be transferred per entangled pair of qubits. It is worth 
mentioning that in this protocol same symbol can be used for key distribution and Eve's 
detection that enhances the efficiency of the protocol. 
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O ■ I. INTRODUCTION 
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, Quantum key distribution (QKD) provides a secure way for generating a private key between 

^ ' two remote parties and then it can be used to distribute the key among several parties. In public 

key crypto-systems, such as, Rivest Shamir Adleman (RSA), the receiver generates a pair of keys: a 
public key and a private key [l| . The security of the communication relies on determining the prime 
factors of a public key, a large integer. The public key is used to encrypt the message while the 
private key decrypts it. With the advent of quantum computing, it is now possible to factorize very 
large numbers much faster. As a result the security of the RSA can easily be compromised. The 
:irst key distribution protocol using four quantum states was proposed by Bennett and Brassard 
. In 1991, Artur Ekert jsj], by using a different approach to quantum cryptography, proposed 
a key distribution protocol in which entangled pairs of qubits are distributed to Alice and Bob, 
who then extract key bits by measuring their qubits. Enormous efforts have been made to develop 
cryptographic protocols based on quantum mechanics [4-11]. 
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Quantum key distribution is a process in which the legitimate users of communication first es- 
tabhsh a shared secret key by transmitting a classical message and then using that key to encrypt 
(decrypt) the secret message. In the field of quantum cryptography or quantum key distribution, 
important advances have been made in both theoretical and experimental directions. However, 
many open problems remain in both fields, such as bringing theory and application together. 
Indeed, the theoretical tools have recently been applied to study the security of practical imple- 
mentations 



12l |. Furthermore, QKD has been shown to be experimentally feasible [l^. 



In recent years researchers have drawn attention to QKD protocols that involve multilevel 
systems with two parties [14-17], or multiple parties with two- level systems [l^. Motivation of 
multilevel quantum key distribution is that more information can be carried that may increase 
the information flux. Some multilevel protocols have been shown to have greater security against 
eavesdropping attacks . Quantum cryptography offers an entirely new technique for secure 

key distribution where security relies upon the laws of quantum physics instead of computational 
complexity. There are several protocols for quantum cryptography [18-23] and quantum secure 
direct communication [24-26] which involve three-party communication. The "quantum dialogue" 



protocol proposed in reference 



261], offers a direct way to exchange confldential messages, defeats 



the disturbance attack but, in turn, it is vulnerable to the intercept-resend attack [2j 

In this paper, we propose a three-party (Alice, Bob and Charlie) quantum cryptographic pro- 
tocol by using Greenberger-Horne-Zeilinger (GHZ) triplet entangled states. In our protocol, Alice 
can obtain the secret messages of Bob and Charlie by decoding the secrets sent by them. Their 
secret messages exchange is secure and simultaneous. Therefore, our protocol may be feasible in 
near-future technology. Our protocol is secure and efficient in the sense that same symbol can be 
used for key distribution and Eve's detection that enhances the efficiency of the protocol. 



II. THE PROTOCOL 



We consider a multiparty cryptographic task where three parties, Alice, Bob, and Charlie, 
would like to obtain a random string of numbers, so that it can be called as a quantum network. 
In our protocol, the three users of communication Alice, Bob and Charlie share a large number of 
entangled tripartite GHZ states (see figure 1). Alice prepares entangled GHZ triplet states, and 
sends the second qubit to Bob and third qubit to Charlie respectively, who then apply their local 
operations on their individual qubits and send it back to Alice. Alice first applies her local operators 
on her part of qubit and then she performs GHZ measurements. Prior to any key distribution Alice 
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(knowing the set of operators Bob and Charlie would apply) , simulate their actions and construct 
a decoding matrix with elements as expectation values of the coding operators for herself, Bob and 
Charlie (see table 1). Once this decoding matrix is constructed, Alice applies her local unitary 
operators and measure the expectation values for the decoding operators. The elements of the 
decoding matrix depend on the operators applied by Alice, Bob and Charlie. Upon comparing this 
expectation value against the already constructed decoding matrix, Alice would be able to identify 
the unitary operators applied by Bob and Charlie. If Eve performs a measurement on the qubit 
during transmission, the expectation value recorded by Alice would be different and she would be 
able to detect Eve's presence and will use the classical channel to inform Bob and Charlie to ignore 
that particular key. By repeating this process for several times a string of bits is transferred from 
Bob and Charlie to Alice which acts as a secret key for communication. 

Whenever an eavesdropper. Eve, makes any type of measurement in the way then the quantum 
state is disturbed which results a change in the quantum decoding matrix that helps Alice to detect 
the presence of eavesdropper. It is worth to note that in this protocol, Alice needs not to have a 
different record of values for the detection of eavesdropper as in the case of ref . . In our protocol, 
whenever an eavesdropper. Eve, interferes she can very easily be detected by the disturbance of 
the decoding matrix. We check for the security of the protocol for intercept/re-send attacks and 
find it secure against such type of attacks. 

Let's consider that the three parties Alice, Bob and Charlie share a sequence of GHZ triplets 
in the state 

I^ABc) = ^(|000) + i|lll))^^^ (1) 



Now the three parties can locally manipulate their individual qubits. The local 



Bob and Charlie can be represented by the unitary operator Ui of the form 
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operators of Alice, 



U, = cos + sin (2) 
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where i = A, B and C and Ri, Pi are the local operators defined as: 
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where < 0j < vr, — vr < {a^i, < vr. Let Alice, Bob and Charlie agree on that Alice can perform 
the unitary operators Ua {Oa, ctA, f^A)^ while Bob and Charlie, can apply the unitary operators 
Ub (^b) and Uc i^c) respectively. Let all the three parties decide prior to any communication that 
Alice can apply unitary operators Ua (0,0,0) and Ua i'^,'^,'^)- Whereas Bob can encode one bit 
of classical information by the two unitary operations as Ub (0) — > mi, and Ub (tt) — > m2. On the 
other hand, Charlie can encode one bit of classical information by his two unitary operations as 
Uc (0) m-^, and Uc (vr) — > 7714. With the application of local operations of the communicating 
parties, the initial state transforms as 

Pf = {UA'S)UB'^Uc)pABciUA'^UB'S)Uc)^ (4) 

where Pabc ~ \'^ABc) {'^ABc\ density matrix for the quantum state with the basis ordered 

as |000) , |001) , 1 100) , 1 101) , |010) , |011) , |110) and |111). We define the operators used by Alice 
for measurement as 

P^ = $ooo'^ooo + $ooi'^ooi + $110^110 + $010^010 

+$10iVrioi + SoilTToil + $100^100 + SlllTTlll (5) 
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where k = A, B or C and TTrst can be written as a combination of eight GHZ states 
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Vz 

and are the real numbers as selected by the three parties with mutual understanding. The 
result of measurements performed by Alice can be obtained as 



*i,aA,/3A) = 1^(^V/), 



(7) 



where Tr represents the trace of a matrix . 
Let in the quantum line from Alice to Bob or Charlie, there is an eavesdropper, Eve, who 
performs the measurement on the qubit. The action of measurement made by Eve on the qubit 
can be modeled as the action of phase damping channel 
transforms to 
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291 ] . The quantum state after measurement 



P = Pin A 



(8) 



i=0 



where = -y/plO) (0| i = ^/pW (1| ^i^d ^2 = \/l — pi are the Kraus operators. An extension 
to N qubits is achieved by applying the measurement to each qubit in turn resulting 

2 

p ^ ^ A,, . . . . pA\^ ®A\^® A\^ (9) 

i=n 



Using equations (1), (4)-(5) and (7)-(9), the result of measurements performed by Alice can be 



6 



recorded as 
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where 
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The elements of the decoding matrix for Bob and CharHe can be found by putting the appropriate 
values for in the equation (10). Let Alice, Bob and Charlie agree that $^qq = = = 3, 
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helps Alice in establishing the decoding matrix. For the case of no eavesdropping i.e. p 
equation (10), the decoding matrix becomes as given in table 1. 

Bob and Charlie, after applying one of their local unitary operators (known to Alice) on their 
respective qubit, send them back to Alice, who first applies her local unitary operators and then 
calculates the expectation values of the coding operators. Then she compares the measured value 
with the elements of the decoding matrix already present in her library constructed by her simu- 
lation (table 1). Since she is well aware of her own actions (unitary operations), therefore, she will 
have to compare only two columns (one for Bob and the other for Charlie) of the decoding matrix 
(table 1). By doing this she can easily find the unitary operators applied by Bob and Charlie and 
hence she can find the corresponding secret key element that they want to transmit her. Repeating 
this process a secret key is transferred from Bob and Charlie to Alice. 

Whenever there is an eavesdropper. Eve, in the way and performs measurement on the qubit, 
the decoding matrix in this case will change as given in tables 2 and 3, representing the Charlie's 
actions Uc (0) and Uc (vr) respectively. It is easy to check from elements of decoding matrices 
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(tables 1, 2 and 3) that the matrix elements are different from each other for the entire range of p 
from to 1, for any particular choice of symbol to be transmitted from Bob or Charlie to Alice, 
for example, mi. In other words none of the elements of the decoding matrix is repeated for any 
value of p ranging from to 1. Hence, Eve can be detected very easily since Alice is well aware of 
her own action. If the users of communication find the presence of Eve (from the disturbance of 
decoding matrix elements), they will abort communication. By repeating this process for several 
times, a string of bits can be transferred from Bob and Alice to Alice which acts as a secret key for 
communication. In case of intercept /re-send attack, if Eve succeeds in finding the qubit then the 
correlation between Alice and Bob or Alice and Charlie will break and the elements of decoding 
matrix will change, giving an indication of eavesdropping (which can be seen from tables 2 and 
3). Then the Alice will announce the abortion of communication to Bob and Charlie on a classical 
channel. 



As it is clear that the decoding matrix (table 1) is different from decoding matrix (tables 2 
and 3) for all values of p > 0. Whenever for any action of Bob or Charlie, if Alice finds the 
measured elements of the decoding matrix different from the elements that she already has in her 
library (table 1), then she would be able to detect the presence of Eve. One of the most common 
eavesdropping strategy is the catch-and-resend attack. In this attack if Eve succeeds in finding the 
bit, she can re-sends a similar bit to Alice. But in our case if it so happens then the correlation 
between Alice and Bob or Alice and Charlie will break and the elements of the decoding matrix 
will change that reveals eavesdropping. For example. Bob applies unitary operator Ub (0) on his 
qubit and sends it back to Alice, in the quantum line. Eve performs measurement on the qubit and 
gets either or 1. On the bases of her measurement result. Eve sends |0) or |1) to Alice. If Alice 
applies Ua (0, 0, 0) before measurement then the final state received by her would be either |000) or 
|111) with equal probability. The probability of getting the decoding matrix element (aj,/3j,7j) , 
can be found for n copies to be transmitted and interrupted i of them by Alice, using binomial 
distribution as 



III. SECURITY ANALYSIS 
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In this case the decoding matrix element can be obtained as 
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Then finding the quantity 

(n n n \ 

j;P,a„j;P,A,,j;P,7. , (14) 
i=0 i=0 j=0 / 

we get (4, |, I) which is independent of the number of copies n. In addition, this is not an element 
of the decoding matrix (table 1) for the corresponding action of Alice Ua (0, 0, 0) and hence Eve can 
be detected easily. Now we find out that how many number of copies of input state, Alice requires 
for the detection of Eve. The answer to this question can be given with the help of variance. Since 
for the decoding matrix elements (a = 3, /3 = 3, 7 = 3) and (5 = 5, r/ = 2, A = 2) (as seen from table 
1), the variance with respect to the number of copies n varies as 

f A A A 1 = ('^ ^ = (± J- 

Therefore for this case nine to ten copies are sufficient for Eve's detection. 



IV. CONCLUSIONS 



We devise a multiparty quantum cryptographic protocol using tripartite entangled GHZ states. 
This protocol is efficient since two classical bits can be transferred per entangled pair of qubits. 
In addition, in this protocol same symbol can be used for key distribution and Eve's detection. 
Unitary operators applied by Bob and Charlie on their part of tripartite entangled state encodes 
a classical symbol that can be decoded at receiver's end with the help of a decoding matrix. Eve's 
presence can be detected by the disturbance of the decoding matrix. Furthermore, our protocol is 
secure against intercept-resend attacks. 
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Figure Caption 

Figure 1. Schematic diagram of the protocoL 

Tables Captions 

Table 1. The decoding matrix obtained as a result of Ahce's simulations and in the absence of Eve, 
i.e. p — 0, where first number in the parenthesis corresponds to Alice, the second number corresponds 
to Bob and the third number corresponds to Charlie respectively. 

Table 2. The decoding matrix obtained as a result of measurements performed by Alice (for Charlie's 
action Uc (0)) in the presence of Eve. 

Table 3. The decoding matrix obtained as a result of measurements performed by Alice (for Charlie's 
action Uc (tt)) in the presence of Eve. 
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FIG. 1: Schematic diagram of the model. 
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TABLE I: The decoding matrix obtained as a result of Alice's simulations and in the absence of Eve, i.e. 
p = 0, where first number in the parenthesis corresponds to Alice, the second number corresponds to Bob 
and the third number corresponds to Charlie respectively. 





C/c(0) ^ ma 
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C^B(7r) -> rn2 


C/a(0,0,0) 
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TABLE IL The decoding matrix obtained as a result of measurements performed by Alice (for Charlie's 
action Uc (0)) in the presence of Eve. 





Uc{0) ms 


Alice's Operation 


Ub{0) mi 




C/a (0,0,0) 
C/A(7r,7r,7r) 


(2+(l-p),2 + (l-p),2+(l-rt) 
(f + f(l-p),3-(l-p),3-(l-p)) 


(3-(l-rt,| + |(l-p),3-(l-p)) 
(3 + (l-p),3+(l-p),|-f(l-p)) 



TABLE IIL The decoding matrix obtained as a result of measurements performed by Alice (for Charlie's 
action Uc (ti")) in the presence of Eve. 





C^c(7r) 7714 


Alice's Operation 


Ub{0) ^ mi 


C/s(7r) ^ m2 


[/a (0,0,0) 
t/A(7r,7r, tt) 


(3-(l-p),3-(l-p),| + f(l-p)) 
(3 + (l-p),f-f(l-p),3 + (l-p)) 


(|-|(l-p),3+(l-p),3+(l-p)) 
(2-(l-p),2-(l-p),2-(l-p)) 



